CyberRota Analysis
AI-GeneratedThe @backstage/plugin-techdocs-node package prior to version 1.15.4 is vulnerable to arbitrary file read due to unsafe path resolution in TechDocs source tree handling. This flaw allows authenticated users to access files outside the intended documentation boundary, potentially exposing sensitive information depending on the deployment configuration. Organizations using Backstage for developer portals should prioritize updating to version 1.15.4 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by techdocs arbitrary file read via mkdocs snippets. Unsafe path resolution in TechDocs source tree handling allows an authenticated user who can register documentation sources to include content from outside the intended documentation boundary. Depending on deployment, this may expose files readable by the build process. This issue is fixed in version 1.15.4.
Related CVEs
Other vulnerabilities affecting the same vendor(s)